
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Vir-reklama-nelze odstranit
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vir-reklama-nelze odstranit
Zdravím,dostal se mi do PC vir,který mi na netu při kliknutí na jakýkoli obrázek háže otravné reklamy... Jo a taky mi to někdy samo vypíná a zapíná Mozzilu... prosím poraďte... Díky za odpovědi.
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Také zdravím!
Dejte log FRST: http://forum.viry.cz/viewtopic.php?f=13&t=133100 .
Dejte log FRST: http://forum.viry.cz/viewtopic.php?f=13&t=133100 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
Tady je log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by user (administrator) on USER-PC on 20-05-2015 18:56:03
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-01] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\MountPoints2: {9e4c340f-e08a-11e4-bf92-d0509947bc41} - E:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Extension: Mozilla Firefox Hotfixer - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\veggy@veggyAddon.com [2015-05-17]
FF Extension: Zoom It - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{59ccdc4c-aef7-88e7-4f85-7bca4021fb3e} [2015-05-20]
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-10]
Chrome:
=======
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\DEFAULT
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-01] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-01] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-01] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [34640 2012-08-09] (ASRock Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-04-12] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-01] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-03-13] (NVIDIA Corporation)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 18:56 - 2015-05-20 18:57 - 00008768 _____ () C:\Users\user\Desktop\FRST.txt
2015-05-20 18:55 - 2015-05-20 18:56 - 00000000 ____D () C:\FRST
2015-05-20 18:54 - 2015-05-20 18:55 - 00112640 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2015-05-20 18:44 - 2015-05-20 18:44 - 02107904 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2015-05-20 18:00 - 2015-05-20 18:00 - 01222144 _____ () C:\Users\user\Downloads\RSITx64.exe
2015-05-19 16:15 - 2015-05-12 04:34 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-05-19 16:12 - 2015-05-13 08:52 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-19 16:12 - 2015-05-13 08:52 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 42718864 _____ () C:\Windows\system32\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 37741712 _____ () C:\Windows\SysWOW64\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 30478992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 22945424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 17540416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 16145176 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 15858728 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 14455296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 13263568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 11790144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 10972304 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-05-19 16:12 - 2015-05-12 08:27 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 02599056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01099808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01059984 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01050256 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00974480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00939080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00502896 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00408208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00407296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00176064 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-05-18 16:26 - 2015-05-18 16:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-16 13:58 - 2015-05-16 13:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-05-16 13:56 - 2015-05-16 13:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup.exe
2015-05-15 22:56 - 2015-05-16 10:46 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-15 22:16 - 2015-05-20 17:06 - 00000358 _____ () C:\Windows\Tasks\AmiUpdXp.job
2015-05-15 22:16 - 2015-05-15 22:16 - 00003392 _____ () C:\Windows\System32\Tasks\AmiUpdXp
2015-05-15 22:16 - 2015-05-15 22:16 - 00000000 ____D () C:\Users\user\AppData\Local\27267
2015-05-15 21:57 - 2015-05-15 21:57 - 00000000 ____D () C:\ProgramData\DivX
2015-05-15 21:56 - 2015-05-20 17:06 - 00001682 _____ () C:\Windows\Tasks\BYAIAMUF.job
2015-05-15 21:56 - 2015-05-20 17:06 - 00001330 _____ () C:\Windows\Tasks\GNOK.job
2015-05-15 21:56 - 2015-05-16 16:01 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:57 - 00004352 _____ () C:\Windows\System32\Tasks\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 02035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 01380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 00004704 _____ () C:\Windows\System32\Tasks\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 00000000 ____D () C:\Users\user\AppData\Local\globalUpdate
2015-05-15 21:54 - 2015-05-15 21:54 - 00752656 _____ () C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe
2015-05-09 11:09 - 2015-05-10 12:18 - 00000000 ____D () C:\Users\user\Documents\Project CARS
2015-05-09 10:38 - 2015-05-10 12:20 - 00000000 ____D () C:\Program Files (x86)\Project CARS
2015-05-09 10:38 - 2015-05-09 10:38 - 00000810 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS.lnk
2015-05-08 12:34 - 2015-05-09 03:21 - 00000000 ____D () C:\Users\user\Downloads\Project.CARS-RELOADED
2015-05-01 20:00 - 2015-05-01 20:22 - 00000000 ____D () C:\Program Files (x86)\DiRT Rally
2015-05-01 19:53 - 2015-05-01 19:56 - 00000000 ____D () C:\Users\user\Downloads\CPU
2015-04-28 17:29 - 2015-04-28 17:40 - 00000000 ____D () C:\ProgramData\TrackMania
2015-04-28 17:26 - 2015-04-28 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmUnitedForever
2015-04-28 17:22 - 2015-05-06 20:53 - 00000000 ____D () C:\Users\user\Documents\TrackMania
2015-04-28 17:22 - 2015-04-28 17:29 - 00000000 ____D () C:\Program Files (x86)\TmUnitedForever
2015-04-23 20:40 - 2015-05-19 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-23 20:40 - 2015-04-23 20:40 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-23 20:40 - 2015-04-23 20:40 - 00001143 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-21 03:56 - 2015-04-21 15:24 - 00000080 _____ () C:\Users\user\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-04-21 03:53 - 2015-04-21 03:53 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-21 03:03 - 2015-05-15 22:16 - 00000000 ____D () C:\Program Files (x86)\Grand Theft Auto V
2015-04-20 21:35 - 2015-04-20 23:26 - 1438822956 _____ () C:\Users\user\Downloads\gfnu.part32.rar
2015-04-20 18:59 - 2015-04-20 21:33 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part31.rar
2015-04-20 16:16 - 2015-04-20 18:57 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part30.rar
2015-04-20 13:33 - 2015-04-20 16:05 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part29.rar
2015-04-20 04:33 - 2015-04-20 07:06 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part28.rar
2015-04-20 01:13 - 2015-04-20 03:53 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part27.rar
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 18:02 - 2015-04-10 05:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-20 17:14 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-20 17:14 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-20 17:12 - 2011-04-12 10:34 - 00665706 _____ () C:\Windows\system32\perfh005.dat
2015-05-20 17:12 - 2011-04-12 10:34 - 00139402 _____ () C:\Windows\system32\perfc005.dat
2015-05-20 17:12 - 2009-07-14 07:13 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 17:10 - 2013-10-03 01:21 - 00947975 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 17:06 - 2015-04-17 22:04 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-20 17:06 - 2015-04-17 21:58 - 00011244 _____ () C:\Windows\setupact.log
2015-05-20 17:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-19 16:16 - 2015-04-09 03:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-05-19 16:16 - 2015-04-09 03:04 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-05-19 16:14 - 2015-04-09 02:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-05-17 10:10 - 2015-04-12 20:48 - 00000000 ____D () C:\Program Files (x86)\GIGABYTE
2015-05-16 23:30 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Hry
2015-05-16 23:28 - 2015-02-21 00:38 - 00000227 _____ () C:\Users\user\Desktop\Nový textový dokument.txt
2015-05-16 22:35 - 2013-10-03 02:08 - 00000000 ____D () C:\Users\user\Documents\FLiNGTrainer
2015-05-16 20:41 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Programy
2015-05-16 14:02 - 2013-10-03 02:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 14:01 - 2015-04-14 00:09 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-05-16 10:47 - 2015-04-12 20:51 - 00000000 ____D () C:\Users\user\Documents\temp
2015-05-15 21:56 - 2013-10-03 02:35 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-13 08:52 - 2015-04-17 22:02 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27 - 2015-04-17 22:33 - 15048816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 12849056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 03363224 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 02971776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 00031710 _____ () C:\Windows\system32\nvinfo.pb
2015-05-12 05:30 - 2015-04-17 22:04 - 06872392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 03490448 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00937288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-05-12 05:30 - 2015-04-17 22:04 - 00385352 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-05-11 19:01 - 2015-04-17 22:04 - 04391871 _____ () C:\Windows\system32\nvcoproc.bin
2015-05-09 07:08 - 2015-04-12 11:39 - 00000000 ____D () C:\Users\user\AppData\Roaming\BitTorrent
2015-05-09 00:23 - 2014-03-01 23:40 - 00000000 ____D () C:\Games
2015-05-08 12:31 - 2015-04-09 06:14 - 00000000 ____D () C:\ProgramData\Codemasters
2015-05-08 12:31 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-01 20:22 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\My Games
2015-05-01 18:51 - 2015-04-09 03:07 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-01 18:51 - 2015-04-09 03:07 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-29 17:59 - 2015-04-09 03:12 - 00000000 ____D () C:\Users\user\AppData\Local\Ahead
2015-04-29 17:59 - 2013-10-03 02:27 - 00000000 ____D () C:\Users\user\AppData\Roaming\Ahead
2015-04-28 17:28 - 2015-04-19 00:18 - 00208662 _____ () C:\Windows\DirectX.log
2015-04-28 16:31 - 2015-04-19 00:24 - 00000000 ____D () C:\ProgramData\TrackMania United
2015-04-24 13:59 - 2015-04-19 14:27 - 00000668 _____ () C:\Windows\PFRO.log
2015-04-21 03:55 - 2015-04-14 20:07 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2015-04-21 03:55 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\Rockstar Games
2015-04-20 00:40 - 2015-04-19 22:02 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part26.rar
==================== Files in the root of some directories =======
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\user\AppData\Roaming\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 2035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-01-25 18:12 - 2015-01-25 18:12 - 0002086 _____ () C:\Users\user\AppData\Roaming\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 1380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
C:\Users\user\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-16 11:28
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:465.66 GB) (Free:173.27 GB) NTFS
Available physical RAM: 2499.01 MB
Total physical RAM: 4095.24 MB
Percentage of memory in use: 38%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 63E08658)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\user\AppData\Local\27267\Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\BYAIAMUF.job => C:\Users\user\AppData\Roaming\BYAIAMUF.exe <==== ATTENTION
Task: C:\Windows\Tasks\GNOK.job => C:\Users\user\AppData\Roaming\GNOK.exe <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe:typelib
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\user\Desktop" je 36 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by user (administrator) on USER-PC on 20-05-2015 18:56:03
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-01] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\MountPoints2: {9e4c340f-e08a-11e4-bf92-d0509947bc41} - E:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Extension: Mozilla Firefox Hotfixer - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\veggy@veggyAddon.com [2015-05-17]
FF Extension: Zoom It - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{59ccdc4c-aef7-88e7-4f85-7bca4021fb3e} [2015-05-20]
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-10]
Chrome:
=======
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\DEFAULT
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-01] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-01] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-01] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [34640 2012-08-09] (ASRock Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-04-12] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-01] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-03-13] (NVIDIA Corporation)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 18:56 - 2015-05-20 18:57 - 00008768 _____ () C:\Users\user\Desktop\FRST.txt
2015-05-20 18:55 - 2015-05-20 18:56 - 00000000 ____D () C:\FRST
2015-05-20 18:54 - 2015-05-20 18:55 - 00112640 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2015-05-20 18:44 - 2015-05-20 18:44 - 02107904 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2015-05-20 18:00 - 2015-05-20 18:00 - 01222144 _____ () C:\Users\user\Downloads\RSITx64.exe
2015-05-19 16:15 - 2015-05-12 04:34 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-05-19 16:12 - 2015-05-13 08:52 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-19 16:12 - 2015-05-13 08:52 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 42718864 _____ () C:\Windows\system32\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 37741712 _____ () C:\Windows\SysWOW64\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 30478992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 22945424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 17540416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 16145176 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 15858728 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 14455296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 13263568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 11790144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 10972304 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-05-19 16:12 - 2015-05-12 08:27 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 02599056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01099808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01059984 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01050256 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00974480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00939080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00502896 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00408208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00407296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00176064 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-05-18 16:26 - 2015-05-18 16:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-16 13:58 - 2015-05-16 13:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-05-16 13:56 - 2015-05-16 13:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup.exe
2015-05-15 22:56 - 2015-05-16 10:46 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-15 22:16 - 2015-05-20 17:06 - 00000358 _____ () C:\Windows\Tasks\AmiUpdXp.job
2015-05-15 22:16 - 2015-05-15 22:16 - 00003392 _____ () C:\Windows\System32\Tasks\AmiUpdXp
2015-05-15 22:16 - 2015-05-15 22:16 - 00000000 ____D () C:\Users\user\AppData\Local\27267
2015-05-15 21:57 - 2015-05-15 21:57 - 00000000 ____D () C:\ProgramData\DivX
2015-05-15 21:56 - 2015-05-20 17:06 - 00001682 _____ () C:\Windows\Tasks\BYAIAMUF.job
2015-05-15 21:56 - 2015-05-20 17:06 - 00001330 _____ () C:\Windows\Tasks\GNOK.job
2015-05-15 21:56 - 2015-05-16 16:01 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:57 - 00004352 _____ () C:\Windows\System32\Tasks\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 02035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 01380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 00004704 _____ () C:\Windows\System32\Tasks\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 00000000 ____D () C:\Users\user\AppData\Local\globalUpdate
2015-05-15 21:54 - 2015-05-15 21:54 - 00752656 _____ () C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe
2015-05-09 11:09 - 2015-05-10 12:18 - 00000000 ____D () C:\Users\user\Documents\Project CARS
2015-05-09 10:38 - 2015-05-10 12:20 - 00000000 ____D () C:\Program Files (x86)\Project CARS
2015-05-09 10:38 - 2015-05-09 10:38 - 00000810 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS.lnk
2015-05-08 12:34 - 2015-05-09 03:21 - 00000000 ____D () C:\Users\user\Downloads\Project.CARS-RELOADED
2015-05-01 20:00 - 2015-05-01 20:22 - 00000000 ____D () C:\Program Files (x86)\DiRT Rally
2015-05-01 19:53 - 2015-05-01 19:56 - 00000000 ____D () C:\Users\user\Downloads\CPU
2015-04-28 17:29 - 2015-04-28 17:40 - 00000000 ____D () C:\ProgramData\TrackMania
2015-04-28 17:26 - 2015-04-28 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmUnitedForever
2015-04-28 17:22 - 2015-05-06 20:53 - 00000000 ____D () C:\Users\user\Documents\TrackMania
2015-04-28 17:22 - 2015-04-28 17:29 - 00000000 ____D () C:\Program Files (x86)\TmUnitedForever
2015-04-23 20:40 - 2015-05-19 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-23 20:40 - 2015-04-23 20:40 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-23 20:40 - 2015-04-23 20:40 - 00001143 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-21 03:56 - 2015-04-21 15:24 - 00000080 _____ () C:\Users\user\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-04-21 03:53 - 2015-04-21 03:53 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-21 03:03 - 2015-05-15 22:16 - 00000000 ____D () C:\Program Files (x86)\Grand Theft Auto V
2015-04-20 21:35 - 2015-04-20 23:26 - 1438822956 _____ () C:\Users\user\Downloads\gfnu.part32.rar
2015-04-20 18:59 - 2015-04-20 21:33 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part31.rar
2015-04-20 16:16 - 2015-04-20 18:57 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part30.rar
2015-04-20 13:33 - 2015-04-20 16:05 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part29.rar
2015-04-20 04:33 - 2015-04-20 07:06 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part28.rar
2015-04-20 01:13 - 2015-04-20 03:53 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part27.rar
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 18:02 - 2015-04-10 05:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-20 17:14 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-20 17:14 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-20 17:12 - 2011-04-12 10:34 - 00665706 _____ () C:\Windows\system32\perfh005.dat
2015-05-20 17:12 - 2011-04-12 10:34 - 00139402 _____ () C:\Windows\system32\perfc005.dat
2015-05-20 17:12 - 2009-07-14 07:13 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 17:10 - 2013-10-03 01:21 - 00947975 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 17:06 - 2015-04-17 22:04 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-20 17:06 - 2015-04-17 21:58 - 00011244 _____ () C:\Windows\setupact.log
2015-05-20 17:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-19 16:16 - 2015-04-09 03:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-05-19 16:16 - 2015-04-09 03:04 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-05-19 16:14 - 2015-04-09 02:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-05-17 10:10 - 2015-04-12 20:48 - 00000000 ____D () C:\Program Files (x86)\GIGABYTE
2015-05-16 23:30 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Hry
2015-05-16 23:28 - 2015-02-21 00:38 - 00000227 _____ () C:\Users\user\Desktop\Nový textový dokument.txt
2015-05-16 22:35 - 2013-10-03 02:08 - 00000000 ____D () C:\Users\user\Documents\FLiNGTrainer
2015-05-16 20:41 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Programy
2015-05-16 14:02 - 2013-10-03 02:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 14:01 - 2015-04-14 00:09 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-05-16 10:47 - 2015-04-12 20:51 - 00000000 ____D () C:\Users\user\Documents\temp
2015-05-15 21:56 - 2013-10-03 02:35 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-13 08:52 - 2015-04-17 22:02 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27 - 2015-04-17 22:33 - 15048816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 12849056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 03363224 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 02971776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 00031710 _____ () C:\Windows\system32\nvinfo.pb
2015-05-12 05:30 - 2015-04-17 22:04 - 06872392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 03490448 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00937288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-05-12 05:30 - 2015-04-17 22:04 - 00385352 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-05-11 19:01 - 2015-04-17 22:04 - 04391871 _____ () C:\Windows\system32\nvcoproc.bin
2015-05-09 07:08 - 2015-04-12 11:39 - 00000000 ____D () C:\Users\user\AppData\Roaming\BitTorrent
2015-05-09 00:23 - 2014-03-01 23:40 - 00000000 ____D () C:\Games
2015-05-08 12:31 - 2015-04-09 06:14 - 00000000 ____D () C:\ProgramData\Codemasters
2015-05-08 12:31 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-01 20:22 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\My Games
2015-05-01 18:51 - 2015-04-09 03:07 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-01 18:51 - 2015-04-09 03:07 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-29 17:59 - 2015-04-09 03:12 - 00000000 ____D () C:\Users\user\AppData\Local\Ahead
2015-04-29 17:59 - 2013-10-03 02:27 - 00000000 ____D () C:\Users\user\AppData\Roaming\Ahead
2015-04-28 17:28 - 2015-04-19 00:18 - 00208662 _____ () C:\Windows\DirectX.log
2015-04-28 16:31 - 2015-04-19 00:24 - 00000000 ____D () C:\ProgramData\TrackMania United
2015-04-24 13:59 - 2015-04-19 14:27 - 00000668 _____ () C:\Windows\PFRO.log
2015-04-21 03:55 - 2015-04-14 20:07 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2015-04-21 03:55 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\Rockstar Games
2015-04-20 00:40 - 2015-04-19 22:02 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part26.rar
==================== Files in the root of some directories =======
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\user\AppData\Roaming\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 2035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-01-25 18:12 - 2015-01-25 18:12 - 0002086 _____ () C:\Users\user\AppData\Roaming\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 1380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
C:\Users\user\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-16 11:28
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:465.66 GB) (Free:173.27 GB) NTFS
Available physical RAM: 2499.01 MB
Total physical RAM: 4095.24 MB
Percentage of memory in use: 38%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 63E08658)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\user\AppData\Local\27267\Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\BYAIAMUF.job => C:\Users\user\AppData\Roaming\BYAIAMUF.exe <==== ATTENTION
Task: C:\Windows\Tasks\GNOK.job => C:\Users\user\AppData\Roaming\GNOK.exe <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe:typelib
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\user\Desktop" je 36 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
# AdwCleaner v4.204 - Log vytvořen 20/05/2015 v 19:32:19
# Aktualizováno 12/05/2015 by Xplode
# Databáze : 2015-05-20.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : user - USER-PC
# Spuštěno z : C:\Users\user\Desktop\adwcleaner_4.204.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\users\user\AppData\Local\globalUpdate
Složka Smazáno : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\veggy@veggyAddon.com
***** [ Naplánované úlohy ] *****
Úloha Smazáno : AmiUpdXp
***** [ Zástupci ] *****
***** [ Registry ] *****
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\ZoomWebLists
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v38.0.1 (x86 cs)
[61a7hncn.default\prefs.js] - Řádek Smazáno : user_pref("extensions.crossrider.bic", "14d5bfb0fcb05b0f3449851bada63b85");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [1525 bytů] - [20/05/2015 19:28:41]
AdwCleaner[S0].txt - [1399 bytů] - [20/05/2015 19:32:19]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1457 bytů] ##########
# Aktualizováno 12/05/2015 by Xplode
# Databáze : 2015-05-20.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : user - USER-PC
# Spuštěno z : C:\Users\user\Desktop\adwcleaner_4.204.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\users\user\AppData\Local\globalUpdate
Složka Smazáno : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\veggy@veggyAddon.com
***** [ Naplánované úlohy ] *****
Úloha Smazáno : AmiUpdXp
***** [ Zástupci ] *****
***** [ Registry ] *****
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\ZoomWebLists
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
***** [ Prohlížeče ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v38.0.1 (x86 cs)
[61a7hncn.default\prefs.js] - Řádek Smazáno : user_pref("extensions.crossrider.bic", "14d5bfb0fcb05b0f3449851bada63b85");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [1525 bytů] - [20/05/2015 19:28:41]
AdwCleaner[S0].txt - [1399 bytů] - [20/05/2015 19:32:19]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1457 bytů] ##########
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by user (administrator) on USER-PC on 20-05-2015 19:42:57
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-01] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\MountPoints2: {9e4c340f-e08a-11e4-bf92-d0509947bc41} - E:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Extension: Zoom It - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{59ccdc4c-aef7-88e7-4f85-7bca4021fb3e} [2015-05-20]
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-10]
Chrome:
=======
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\DEFAULT
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-01] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-01] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-01] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [34640 2012-08-09] (ASRock Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-04-12] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-01] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-03-13] (NVIDIA Corporation)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 19:42 - 2015-05-20 19:42 - 00029696 _____ () C:\Users\user\AppData\Local\MSGBOX.EXE
2015-05-20 19:42 - 2015-05-20 19:42 - 00015327 _____ () C:\Users\user\Desktop\LM.bat
2015-05-20 19:27 - 2015-05-20 19:32 - 00000000 ____D () C:\AdwCleaner
2015-05-20 19:27 - 2015-05-20 19:27 - 02209792 _____ () C:\Users\user\Desktop\adwcleaner_4.204.exe
2015-05-20 18:56 - 2015-05-20 19:43 - 00008990 _____ () C:\Users\user\Desktop\FRST.txt
2015-05-20 18:55 - 2015-05-20 19:42 - 00000000 ____D () C:\FRST
2015-05-20 18:54 - 2015-05-20 18:55 - 00112640 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2015-05-20 18:44 - 2015-05-20 18:44 - 02107904 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2015-05-20 18:00 - 2015-05-20 18:00 - 01222144 _____ () C:\Users\user\Downloads\RSITx64.exe
2015-05-19 16:15 - 2015-05-12 04:34 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-05-19 16:12 - 2015-05-13 08:52 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-19 16:12 - 2015-05-13 08:52 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 42718864 _____ () C:\Windows\system32\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 37741712 _____ () C:\Windows\SysWOW64\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 30478992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 22945424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 17540416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 16145176 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 15858728 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 14455296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 13263568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 11790144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 10972304 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-05-19 16:12 - 2015-05-12 08:27 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 02599056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01099808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01059984 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01050256 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00974480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00939080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00502896 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00408208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00407296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00176064 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-05-18 16:26 - 2015-05-18 16:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-16 13:58 - 2015-05-16 13:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-05-16 13:56 - 2015-05-16 13:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup.exe
2015-05-15 22:56 - 2015-05-16 10:46 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-15 22:16 - 2015-05-15 22:16 - 00000000 ____D () C:\Users\user\AppData\Local\27267
2015-05-15 21:57 - 2015-05-15 21:57 - 00000000 ____D () C:\ProgramData\DivX
2015-05-15 21:56 - 2015-05-20 19:33 - 00001682 _____ () C:\Windows\Tasks\BYAIAMUF.job
2015-05-15 21:56 - 2015-05-20 19:33 - 00001330 _____ () C:\Windows\Tasks\GNOK.job
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:57 - 00004352 _____ () C:\Windows\System32\Tasks\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 02035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 01380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 00004704 _____ () C:\Windows\System32\Tasks\BYAIAMUF
2015-05-15 21:54 - 2015-05-15 21:54 - 00752656 _____ () C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe
2015-05-09 11:09 - 2015-05-10 12:18 - 00000000 ____D () C:\Users\user\Documents\Project CARS
2015-05-09 10:38 - 2015-05-10 12:20 - 00000000 ____D () C:\Program Files (x86)\Project CARS
2015-05-09 10:38 - 2015-05-09 10:38 - 00000810 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS.lnk
2015-05-08 12:34 - 2015-05-09 03:21 - 00000000 ____D () C:\Users\user\Downloads\Project.CARS-RELOADED
2015-05-01 20:00 - 2015-05-01 20:22 - 00000000 ____D () C:\Program Files (x86)\DiRT Rally
2015-05-01 19:53 - 2015-05-01 19:56 - 00000000 ____D () C:\Users\user\Downloads\CPU
2015-04-28 17:29 - 2015-04-28 17:40 - 00000000 ____D () C:\ProgramData\TrackMania
2015-04-28 17:26 - 2015-04-28 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmUnitedForever
2015-04-28 17:22 - 2015-05-06 20:53 - 00000000 ____D () C:\Users\user\Documents\TrackMania
2015-04-28 17:22 - 2015-04-28 17:29 - 00000000 ____D () C:\Program Files (x86)\TmUnitedForever
2015-04-23 20:40 - 2015-05-19 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-23 20:40 - 2015-04-23 20:40 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-23 20:40 - 2015-04-23 20:40 - 00001143 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-21 03:56 - 2015-04-21 15:24 - 00000080 _____ () C:\Users\user\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-04-21 03:53 - 2015-04-21 03:53 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-21 03:03 - 2015-05-15 22:16 - 00000000 ____D () C:\Program Files (x86)\Grand Theft Auto V
2015-04-20 21:35 - 2015-04-20 23:26 - 1438822956 _____ () C:\Users\user\Downloads\gfnu.part32.rar
2015-04-20 18:59 - 2015-04-20 21:33 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part31.rar
2015-04-20 16:16 - 2015-04-20 18:57 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part30.rar
2015-04-20 13:33 - 2015-04-20 16:05 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part29.rar
2015-04-20 04:33 - 2015-04-20 07:06 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part28.rar
2015-04-20 01:13 - 2015-04-20 03:53 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part27.rar
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 19:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-20 19:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-20 19:39 - 2011-04-12 10:34 - 00665706 _____ () C:\Windows\system32\perfh005.dat
2015-05-20 19:39 - 2011-04-12 10:34 - 00139402 _____ () C:\Windows\system32\perfc005.dat
2015-05-20 19:39 - 2009-07-14 07:13 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 19:36 - 2013-10-03 01:21 - 00951829 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 19:33 - 2015-04-17 22:04 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-20 19:33 - 2015-04-17 21:58 - 00011412 _____ () C:\Windows\setupact.log
2015-05-20 19:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-20 19:02 - 2015-04-10 05:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-19 16:16 - 2015-04-09 03:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-05-19 16:16 - 2015-04-09 03:04 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-05-19 16:14 - 2015-04-09 02:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-05-17 10:10 - 2015-04-12 20:48 - 00000000 ____D () C:\Program Files (x86)\GIGABYTE
2015-05-16 23:30 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Hry
2015-05-16 23:28 - 2015-02-21 00:38 - 00000227 _____ () C:\Users\user\Desktop\Nový textový dokument.txt
2015-05-16 22:35 - 2013-10-03 02:08 - 00000000 ____D () C:\Users\user\Documents\FLiNGTrainer
2015-05-16 20:41 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Programy
2015-05-16 14:02 - 2013-10-03 02:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 14:01 - 2015-04-14 00:09 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-05-16 10:47 - 2015-04-12 20:51 - 00000000 ____D () C:\Users\user\Documents\temp
2015-05-15 21:56 - 2013-10-03 02:35 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-13 08:52 - 2015-04-17 22:02 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27 - 2015-04-17 22:33 - 15048816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 12849056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 03363224 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 02971776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 00031710 _____ () C:\Windows\system32\nvinfo.pb
2015-05-12 05:30 - 2015-04-17 22:04 - 06872392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 03490448 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00937288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-05-12 05:30 - 2015-04-17 22:04 - 00385352 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-05-11 19:01 - 2015-04-17 22:04 - 04391871 _____ () C:\Windows\system32\nvcoproc.bin
2015-05-09 07:08 - 2015-04-12 11:39 - 00000000 ____D () C:\Users\user\AppData\Roaming\BitTorrent
2015-05-09 00:23 - 2014-03-01 23:40 - 00000000 ____D () C:\Games
2015-05-08 12:31 - 2015-04-09 06:14 - 00000000 ____D () C:\ProgramData\Codemasters
2015-05-08 12:31 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-01 20:22 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\My Games
2015-05-01 18:51 - 2015-04-09 03:07 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-01 18:51 - 2015-04-09 03:07 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-29 17:59 - 2015-04-09 03:12 - 00000000 ____D () C:\Users\user\AppData\Local\Ahead
2015-04-29 17:59 - 2013-10-03 02:27 - 00000000 ____D () C:\Users\user\AppData\Roaming\Ahead
2015-04-28 17:28 - 2015-04-19 00:18 - 00208662 _____ () C:\Windows\DirectX.log
2015-04-28 16:31 - 2015-04-19 00:24 - 00000000 ____D () C:\ProgramData\TrackMania United
2015-04-24 13:59 - 2015-04-19 14:27 - 00000668 _____ () C:\Windows\PFRO.log
2015-04-21 03:55 - 2015-04-14 20:07 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2015-04-21 03:55 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\Rockstar Games
2015-04-20 00:40 - 2015-04-19 22:02 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part26.rar
==================== Files in the root of some directories =======
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\user\AppData\Roaming\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 2035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-01-25 18:12 - 2015-01-25 18:12 - 0002086 _____ () C:\Users\user\AppData\Roaming\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 1380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-20 19:42 - 2015-05-20 19:42 - 0029696 _____ () C:\Users\user\AppData\Local\MSGBOX.EXE
Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
C:\Users\user\AppData\Local\Temp\Quarantine.exe
C:\Users\user\AppData\Local\Temp\sqlite3.dll
C:\Users\user\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-16 11:28
==================== End Of Log ============================
Ran by user (administrator) on USER-PC on 20-05-2015 19:42:57
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-01] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG)
HKU\S-1-5-21-2742894317-591351379-30404887-1000\...\MountPoints2: {9e4c340f-e08a-11e4-bf92-d0509947bc41} - E:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Extension: Zoom It - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{59ccdc4c-aef7-88e7-4f85-7bca4021fb3e} [2015-05-20]
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\61a7hncn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-10]
Chrome:
=======
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\DEFAULT
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-01] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-01] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-01] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [34640 2012-08-09] (ASRock Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-04-12] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-01] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-03-13] (NVIDIA Corporation)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 19:42 - 2015-05-20 19:42 - 00029696 _____ () C:\Users\user\AppData\Local\MSGBOX.EXE
2015-05-20 19:42 - 2015-05-20 19:42 - 00015327 _____ () C:\Users\user\Desktop\LM.bat
2015-05-20 19:27 - 2015-05-20 19:32 - 00000000 ____D () C:\AdwCleaner
2015-05-20 19:27 - 2015-05-20 19:27 - 02209792 _____ () C:\Users\user\Desktop\adwcleaner_4.204.exe
2015-05-20 18:56 - 2015-05-20 19:43 - 00008990 _____ () C:\Users\user\Desktop\FRST.txt
2015-05-20 18:55 - 2015-05-20 19:42 - 00000000 ____D () C:\FRST
2015-05-20 18:54 - 2015-05-20 18:55 - 00112640 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2015-05-20 18:44 - 2015-05-20 18:44 - 02107904 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2015-05-20 18:00 - 2015-05-20 18:00 - 01222144 _____ () C:\Users\user\Downloads\RSITx64.exe
2015-05-19 16:15 - 2015-05-12 04:34 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-05-19 16:12 - 2015-05-13 08:52 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-19 16:12 - 2015-05-13 08:52 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 42718864 _____ () C:\Windows\system32\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 37741712 _____ () C:\Windows\SysWOW64\nvcompiler.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 30478992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 22945424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 17540416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 16145176 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 15858728 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 14455296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 13263568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 11790144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 10972304 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-05-19 16:12 - 2015-05-12 08:27 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 02599056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435286.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01099808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01059984 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 01050256 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00974480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00939080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00502896 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00408208 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00407296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00176064 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-05-19 16:12 - 2015-05-12 08:27 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-05-18 16:26 - 2015-05-18 16:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-16 13:58 - 2015-05-16 13:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-05-16 13:56 - 2015-05-16 13:57 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup.exe
2015-05-15 22:56 - 2015-05-16 10:46 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-15 22:16 - 2015-05-15 22:16 - 00000000 ____D () C:\Users\user\AppData\Local\27267
2015-05-15 21:57 - 2015-05-15 21:57 - 00000000 ____D () C:\ProgramData\DivX
2015-05-15 21:56 - 2015-05-20 19:33 - 00001682 _____ () C:\Windows\Tasks\BYAIAMUF.job
2015-05-15 21:56 - 2015-05-20 19:33 - 00001330 _____ () C:\Windows\Tasks\GNOK.job
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Users\user\AppData\Roaming\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2015-05-15 21:56 - 2015-05-15 21:57 - 00004352 _____ () C:\Windows\System32\Tasks\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 02035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 01380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-15 21:56 - 2015-05-15 21:56 - 00004704 _____ () C:\Windows\System32\Tasks\BYAIAMUF
2015-05-15 21:54 - 2015-05-15 21:54 - 00752656 _____ () C:\Users\user\Downloads\DivX.Web.Player.Installer__8420_il261.exe
2015-05-09 11:09 - 2015-05-10 12:18 - 00000000 ____D () C:\Users\user\Documents\Project CARS
2015-05-09 10:38 - 2015-05-10 12:20 - 00000000 ____D () C:\Program Files (x86)\Project CARS
2015-05-09 10:38 - 2015-05-09 10:38 - 00000810 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS.lnk
2015-05-08 12:34 - 2015-05-09 03:21 - 00000000 ____D () C:\Users\user\Downloads\Project.CARS-RELOADED
2015-05-01 20:00 - 2015-05-01 20:22 - 00000000 ____D () C:\Program Files (x86)\DiRT Rally
2015-05-01 19:53 - 2015-05-01 19:56 - 00000000 ____D () C:\Users\user\Downloads\CPU
2015-04-28 17:29 - 2015-04-28 17:40 - 00000000 ____D () C:\ProgramData\TrackMania
2015-04-28 17:26 - 2015-04-28 17:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmUnitedForever
2015-04-28 17:22 - 2015-05-06 20:53 - 00000000 ____D () C:\Users\user\Documents\TrackMania
2015-04-28 17:22 - 2015-04-28 17:29 - 00000000 ____D () C:\Program Files (x86)\TmUnitedForever
2015-04-23 20:40 - 2015-05-19 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-23 20:40 - 2015-04-23 20:40 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-23 20:40 - 2015-04-23 20:40 - 00001143 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-21 03:56 - 2015-04-21 15:24 - 00000080 _____ () C:\Users\user\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-04-21 03:53 - 2015-04-21 03:53 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-21 03:03 - 2015-05-15 22:16 - 00000000 ____D () C:\Program Files (x86)\Grand Theft Auto V
2015-04-20 21:35 - 2015-04-20 23:26 - 1438822956 _____ () C:\Users\user\Downloads\gfnu.part32.rar
2015-04-20 18:59 - 2015-04-20 21:33 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part31.rar
2015-04-20 16:16 - 2015-04-20 18:57 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part30.rar
2015-04-20 13:33 - 2015-04-20 16:05 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part29.rar
2015-04-20 04:33 - 2015-04-20 07:06 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part28.rar
2015-04-20 01:13 - 2015-04-20 03:53 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part27.rar
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 19:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-20 19:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-20 19:39 - 2011-04-12 10:34 - 00665706 _____ () C:\Windows\system32\perfh005.dat
2015-05-20 19:39 - 2011-04-12 10:34 - 00139402 _____ () C:\Windows\system32\perfc005.dat
2015-05-20 19:39 - 2009-07-14 07:13 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 19:36 - 2013-10-03 01:21 - 00951829 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 19:33 - 2015-04-17 22:04 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-20 19:33 - 2015-04-17 21:58 - 00011412 _____ () C:\Windows\setupact.log
2015-05-20 19:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-20 19:02 - 2015-04-10 05:06 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-19 16:16 - 2015-04-09 03:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-05-19 16:16 - 2015-04-09 03:04 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-05-19 16:14 - 2015-04-09 02:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-05-17 10:10 - 2015-04-12 20:48 - 00000000 ____D () C:\Program Files (x86)\GIGABYTE
2015-05-16 23:30 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Hry
2015-05-16 23:28 - 2015-02-21 00:38 - 00000227 _____ () C:\Users\user\Desktop\Nový textový dokument.txt
2015-05-16 22:35 - 2013-10-03 02:08 - 00000000 ____D () C:\Users\user\Documents\FLiNGTrainer
2015-05-16 20:41 - 2013-10-03 02:05 - 00000000 ____D () C:\Users\user\Desktop\Programy
2015-05-16 14:02 - 2013-10-03 02:00 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-16 14:01 - 2015-04-14 00:09 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-05-16 10:47 - 2015-04-12 20:51 - 00000000 ____D () C:\Users\user\Documents\temp
2015-05-15 21:56 - 2013-10-03 02:35 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-13 08:52 - 2015-04-17 22:02 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27 - 2015-04-17 22:33 - 15048816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:03 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 12849056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 03363224 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 02971776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-12 08:27 - 2015-04-17 22:02 - 00031710 _____ () C:\Windows\system32\nvinfo.pb
2015-05-12 05:30 - 2015-04-17 22:04 - 06872392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 03490448 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00937288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-05-12 05:30 - 2015-04-17 22:04 - 00385352 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-05-12 05:30 - 2015-04-17 22:04 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-05-11 19:01 - 2015-04-17 22:04 - 04391871 _____ () C:\Windows\system32\nvcoproc.bin
2015-05-09 07:08 - 2015-04-12 11:39 - 00000000 ____D () C:\Users\user\AppData\Roaming\BitTorrent
2015-05-09 00:23 - 2014-03-01 23:40 - 00000000 ____D () C:\Games
2015-05-08 12:31 - 2015-04-09 06:14 - 00000000 ____D () C:\ProgramData\Codemasters
2015-05-08 12:31 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-01 20:22 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\My Games
2015-05-01 18:51 - 2015-04-09 03:07 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-01 18:51 - 2015-04-09 03:07 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-01 18:50 - 2015-04-09 03:07 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-29 17:59 - 2015-04-09 03:12 - 00000000 ____D () C:\Users\user\AppData\Local\Ahead
2015-04-29 17:59 - 2013-10-03 02:27 - 00000000 ____D () C:\Users\user\AppData\Roaming\Ahead
2015-04-28 17:28 - 2015-04-19 00:18 - 00208662 _____ () C:\Windows\DirectX.log
2015-04-28 16:31 - 2015-04-19 00:24 - 00000000 ____D () C:\ProgramData\TrackMania United
2015-04-24 13:59 - 2015-04-19 14:27 - 00000668 _____ () C:\Windows\PFRO.log
2015-04-21 03:55 - 2015-04-14 20:07 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2015-04-21 03:55 - 2013-10-03 02:10 - 00000000 ____D () C:\Users\user\Documents\Rockstar Games
2015-04-20 00:40 - 2015-04-19 22:02 - 2096103424 _____ () C:\Users\user\Downloads\gfnu.part26.rar
==================== Files in the root of some directories =======
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\user\AppData\Roaming\BYAIAMUF
2015-05-15 21:56 - 2015-05-15 21:56 - 2035200 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\BYAIAMUF.exe
2015-01-25 18:12 - 2015-01-25 18:12 - 0002086 _____ () C:\Users\user\AppData\Roaming\GNOK
2015-05-15 21:56 - 2015-05-15 21:56 - 1380352 _____ (Cinema PlusV16.03) C:\Users\user\AppData\Roaming\GNOK.exe
2015-05-20 19:42 - 2015-05-20 19:42 - 0029696 _____ () C:\Users\user\AppData\Local\MSGBOX.EXE
Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\mytmpinstaller.exe
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
C:\Users\user\AppData\Local\Temp\Quarantine.exe
C:\Users\user\AppData\Local\Temp\sqlite3.dll
C:\Users\user\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-16 11:28
==================== End Of Log ============================
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Otevřte poznámkový blok a zkopírujte do něj:
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\user\AppData\Local\27267
C:\Windows\Tasks\BYAIAMUF.job
C:\Windows\Tasks\GNOK.job
C:\Users\user\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
C:\Users\user\AppData\Roaming\BYAIAMUF
C:\Users\user\AppData\Roaming\GNOK
C:\Users\user\AppData\Local\Temp
End
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-05-2015
Ran by user at 2015-05-21 14:05:55 Run:1
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\user\AppData\Local\27267
C:\Windows\Tasks\BYAIAMUF.job
C:\Windows\Tasks\GNOK.job
C:\Users\user\AppData\Local???????????????????
C:\Users\user\AppData\Roaming\BYAIAMUF
C:\Users\user\AppData\Roaming\GNOK
C:\Users\user\AppData\Local\Temp
End
*****************
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Users\user\AppData\Local\27267 => Moved successfully.
C:\Windows\Tasks\BYAIAMUF.job => Moved successfully.
C:\Windows\Tasks\GNOK.job => Moved successfully.
"C:\Users\user\AppData\Local???????????????????" directory move:
Could not move "C:\Users\user\AppData\Local???????????????????" directory. => Scheduled to move on reboot.
C:\Users\user\AppData\Roaming\BYAIAMUF => Moved successfully.
C:\Users\user\AppData\Roaming\GNOK => Moved successfully.
"C:\Users\user\AppData\Local\Temp" directory move:
Could not move "C:\Users\user\AppData\Local\Temp" directory. => Scheduled to move on reboot.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-05-21 15:49:29)<=
"C:\Users\user\AppData\Local???????????????????" => Could not move.
C:\Users\user\AppData\Local\Temp => Moved successfully.
==== End of Fixlog 15:49:29 ====
Ran by user at 2015-05-21 14:05:55 Run:1
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\user\AppData\Local\27267
C:\Windows\Tasks\BYAIAMUF.job
C:\Windows\Tasks\GNOK.job
C:\Users\user\AppData\Local???????????????????
C:\Users\user\AppData\Roaming\BYAIAMUF
C:\Users\user\AppData\Roaming\GNOK
C:\Users\user\AppData\Local\Temp
End
*****************
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Users\user\AppData\Local\27267 => Moved successfully.
C:\Windows\Tasks\BYAIAMUF.job => Moved successfully.
C:\Windows\Tasks\GNOK.job => Moved successfully.
"C:\Users\user\AppData\Local???????????????????" directory move:
Could not move "C:\Users\user\AppData\Local???????????????????" directory. => Scheduled to move on reboot.
C:\Users\user\AppData\Roaming\BYAIAMUF => Moved successfully.
C:\Users\user\AppData\Roaming\GNOK => Moved successfully.
"C:\Users\user\AppData\Local\Temp" directory move:
Could not move "C:\Users\user\AppData\Local\Temp" directory. => Scheduled to move on reboot.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-05-21 15:49:29)<=
"C:\Users\user\AppData\Local???????????????????" => Could not move.
C:\Users\user\AppData\Local\Temp => Moved successfully.
==== End of Fixlog 15:49:29 ====
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
nn,je to stejné,furt mi to vyskakuje... dycky mi naskočí taková reklama po kliknutí i do prázdného místa,jak jsem dneska zjistil anebo když jsem se chtěl tady přihlásit,tak to taky vyskočilo... zkusím to vyfotit,abyste věděl,o co jde.
Re: Vir-reklama-nelze odstranit
Zatím se mi podařilo zachytit toto.. u některých slov se mi takto zvýrazní text,na který když najedu,tak je tam reklama a to zelené kolečko se mi taky zdá nějaké pochybné...
- Přílohy
-
- Bez názvu2.jpg (67.04 KiB) Zobrazeno 1721 x
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Vir-reklama-nelze odstranit
ok... jinak už jsem vyfotil tu reklamu,co mi vyskočí po kliknutí,ale nejde mi to tu vložit.
- Rudy
- Site Admin
- Příspěvky: 119320
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Vir-reklama-nelze odstranit
Rád bych viděl ten log. Soubor je možná velký.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.